ComreadinessMemo No. 0284

Technical diligence,
underwritten by evidence.

Point Comreadiness at any repository. In under an hour it returns an evidence-backed Release Readiness Index — every finding cited to the line, every control attested, and the verdict sealed in a certificate any counterparty can independently verify.1

§01
‹ 1hr
to first scored memo
§02
10
weighted domains
§03
Sealed
signed · verifiable
§04
Read-only
zero source egress
Exhibit A · Release Readiness Indexcomreadiness.com/verify
acme-saas · main · 0a7f3b9Live
Release Readiness Index
72/100TIER B
3 blockers284 evidence items
10-domain scorecardweighted
SEC
OPS
ARC
TEN
DOC
TST
REL
DAT
LIC
AIG
  • CRITSEC-014Hardcoded API key in src/integrations/stripe.ts:42L42
  • CRITOPS-007No rollback runbook documented for production deploys-
  • CRITTEN-003Tenant context leaks across logger metadataL88
  • HIGHARC-021Service-layer untested; integration coverage at 14%-
PR draftRemediation for SEC-014 prepared — propose-only, awaiting approval
Signed · independently verifiablesha256:9f3c…a712
Frameworks
04
Specialist agents
30
Deterministic rules
100+
Model panel
Multi-LLM
Deliverables
09
Audit trail
End-to-end
Who it's for

One assessment. Three sides of the table.

The same evidence trail answers a different question depending on where you sit — buying, building, or accountable for the result.

For investors

Know which targets are actually real.

A first-pass technical screen on any target's GitHub — before you spend a partner's afternoon or an advisor's invoice on it.

  • Portfolio triage, side by side
  • Quarterly re-runs track the delta
  • Board- and LP-ready exports
<1 hrto an evidence-backed verdict
How the screen works
For founders

Walk in already knowing the score.

Run the same assessment an acquirer would on your own codebase. Fix what matters before the partner meeting; ignore the rest with receipts.

  • Self-DD before the raise
  • The acquirer's-eye view, early
  • A debt list that's actually triaged
Same rulesthey'll run on you
See what we measure
For team leaders

Give the board a defensible answer.

Engineering, security, and platform leads get an objective, repeatable read on readiness — with the evidence to back every number when someone pushes.

  • An onboarding map for new hires
  • Reconciled across multiple models
  • Audit trail for every claim
Every citetraceable to a control
Inside the method
How it works

From repository to decision, in three movements.

We instrument the technical-readiness portion of diligence so the partner spends their hour on the founder, not the codebase.

Phase 01, Collect

Connect.

Install the read-only GitHub connector (Personal Access Token, scoped to read). Link one repository or an entire organisation. We never clone, publish, or retain source after assessment. Revocable in one click.

Read more
Phase 02, Reason

Assess.

We run 100+ deterministic rules and 30 AI specialist agents against the framework you choose. Every finding cites a control code; code-pattern findings additionally cite a file location (with a line range when the agent can pinpoint it). The rule layer is fully reproducible run-to-run.

Read more
Phase 03, Report

Decide.

Investor-grade report with executive summary, maturity matrix, blocker queue, and remediation workbook. Re-run quarterly to track movement against itself.

Read more
Frameworks

Four lenses. One source of truth.

Most tools generate output. We narrow it. Each framework is a structured rubric of controls, run by specialist agents against real evidence. Modular rule packs by language, framework, deployment target, or compliance regime.

+ 18 modular rule packs
  • FW.0123 controls
    Technical Due Diligence
    Architecture · Documentation · Testing maturity
    Investor / acquirer
  • FW.0251 controls
    Commercial SaaS
    Packaging · Onboarding · Multi-tenant isolation
    Launch readiness
  • FW.0318 controls
    Enterprise Release
    Governance · Rollback · Operational resilience
    Deployment readiness
  • FW.0425 controls
    Security Baseline
    IP & licensing · Secrets · Authorisation
    Posture & provenance
Honest scope

What we replace. What we don't.

Restraint is the feature. Tools that promise everything decide nothing. We compress the technical-readiness portion of diligence and stop there. Knowing where the line is is what makes the signal worth trusting.

Inside scope

What we replace

  • First-pass technical screen on a target's GitHub
  • Architecture, security, ops, and code-quality review
  • Documentation, testing maturity, release governance
  • Reproducible rule findings with file path provenance (line range where available)
  • Cross-target comparison for portfolio triage
Outside scope

What we don't

  • Customer references and revenue / churn analysis
  • Penetration testing or live-system security work
  • Financial DD, legal review of customer contracts
  • Patent / IP search beyond connected source code
  • The judgement of an experienced operator at the table
Multi-model panel

Don't take one model's word for it.

A single model has a single bias. For a decision this consequential, run a panel — several LLMs assess the same evidence independently, and we reconcile them. Agreement is signal. Disagreement is where the real questions live.

Panel · Readiness № 029184% agreement
Claude Sonnet 4.6
78
GPT-4o
72
Gemini 2.5 Pro
81
Arbiter

Models agree the architecture is sound; they split on tenant isolation — GPT-4o flagged it a blocker, the others did not. The evidence (a shared DB schema with no row-level scoping) supports the stricter call. Verify before launch.

Independent verdicts

Pick the models — our managed Claude and GPT, or bring your own key for Gemini, DeepSeek, Mistral, or a self-hosted endpoint. Each one scores the same evidence on its own.

Consensus, and where it breaks

We line the verdicts up: where the models agree you can move; where they diverge — a score gap, a disputed blocker, a finding only one model saw — we surface it precisely.

An arbiter that explains why

A final pass rationalises the disagreement: why the models differ, which call the evidence best supports, and the next step to settle it. Not one opaque score — a reconciled one.

Managed models run under your plan's cost cap. Bring-your-own keys are encrypted at rest and run on your own quota — including private, self-hosted models for sovereign deployments.

For investors
“I don’t need more data. I need to know which five percent matters. That’s what they give me, every quarter, on every company I back. Same investor-grade rigour, same evidence trail, same place to argue with the score.”
JP
Partner
Late-stage technology fund

Portfolio dashboard

Every company you back, side-by-side. Maturity band, risk level, score delta since last quarter.

Trend tracking

Quarterly re-runs surface movement. Know which companies are levelling up, which are sliding.

Risk concentration

Spot which companies in your portfolio are commercially exposed before the board meeting, not in it.

Board-ready exports

Clean HTML report with executive summary, KPIs, matrices, and a remediation queue. Built for LPs, not engineers.

For founders

The founders who walk in already knowing the score are the ones who close it.

Run the same investor-grade assessment on your own codebase. Quarterly self-DD. Decide which technical debts matter enough to ship before the partner meeting. Ignore the rest with receipts in your back pocket.

Pre-fundraise prep

See your score before the partner meeting. Walk in with the receipts, not the surprises.

Acquirer's-eye view

Find what they will flag, before they flag it. Same rules, same agents, same evidence trail.

Engineering north star

Quarterly self-DD so technical debt does not compound silently between board reviews.

Onboarding map

Hand new engineers a structured tour of the system, with the rough edges already labelled.

For team leaders

The answer you can stand behind when the board pushes back.

Engineering, platform, and security leads carry the readiness question between reviews. We make it objective, repeatable, and documented — so “are we ready?” has an answer with an audit trail, not a vibe.

Objective baseline

A repeatable read on readiness that doesn't move with whoever's in the room. Re-run it quarterly and watch the line, not the mood.

Evidence for every claim

Every number traces to a control and a cited file. When the board pushes back, you have the receipt, not an opinion.

Reconciled, not asserted

Run the assessment across multiple models and we show you where they agree, where they don't, and which call the evidence supports.

Onboarding map

Hand a new engineer a structured tour of the system — with the rough edges already labelled and prioritised.

Deliverables

Eleven artefacts. One run.

Every assessment ships distinct deliverables, each built for a different audience — partners, founders, engineers, LPs, auditors — led by a signed, independently-verifiable certificate.

Verifiable certificate

A signed Release Readiness certificate with a public verify link. An investor confirms the score is authentic and untampered without re-running anything — and it can't be doctored after the fact.

SBOM & licence risk

A full software bill of materials with every dependency's licence classified — permissive, copyleft, or prohibited — so GPL/AGPL contamination surfaces before a deal does, not after.

GenAI-code exposure

How much of the codebase shows AI-authorship signals, and whether that AI use is governed — the provenance and IP question every 2026 acquirer now asks.

Executive summary

One page. Board-ready. Plain English score, the three things to fix, the three things working.

Technical findings

Full report with file citations on every code-pattern finding (with line range when the agent can pinpoint it). The evidence behind the score.

Remediation workbook

Quick wins and effort estimates. The list a CTO can hand to their team on Monday morning.

AI-agent script

Machine-readable action plan. Feed it to your in-house coding agent or copy-paste into Cursor.

Code quality report

Maturity scoring across architecture, testing, ops, security, and documentation lenses.

Audit trail

Every rule evaluated, every evidence item cited. So your IC has nothing to argue with the auditor about.

Model comparison

When you run a panel: every model's verdict side by side, where they agree and diverge, and the arbiter's reconciliation. Trust the number because you can see the disagreement.

Processing record

A compliance record of what data was looked at, what happened to it, and what was sent where — without exposing prompts. Built for GDPR Art. 30, SOC 2, and ISO 27001 reviews.

JSON export

Machine-readable findings and evidence. Pipe it into your own tooling, BI stack, or LP dashboard.

Pricing

Priced by portfolio size.

Three subscription tiers, plus Sovereign on the roadmap for self-hosted deployments where source can't touch a third-party LLM. AI cost is BYOK today: bring your own Anthropic or OpenAI key, capped per assessment so spend stays predictable.

Most chosen
Partner
$1,999USD / month

Funds & family offices · BYOK or managed

Join the waitlist
See full pricingNeed a self-hosted deployment with a configurable AI endpoint? Talk to us about Sovereign , scoped per engagement.
Trusted because

The defaults we ship with.

Read-only by design

Read-only GitHub connector. We never clone, publish, or retain source after assessment.

No model training

Your code and findings are never used to train AI models, ours or the providers'.

Auditable evidence

Every finding cites a control; code-pattern findings cite a file location (with a line range when the agent can pinpoint it). No opaque AI scores.

Let's talk

One repo. Thirty minutes. Walk away knowing.

Bring any repository you have read access to. We'll run a live assessment with you. We won't be the loudest tool in your inbox. We'll be the one that earns the second meeting.